PkgRadar

npm · registry.npmjs.org

@thotischner/observability-mcp

Credential file access: matched "KubeConfig"

Why PkgRadar flagged 1.7.1

SeveritySignalEvidence
highCredential file accessmatched "KubeConfig" · package/dist/connectors/kubernetes-client.js
highCredential file accessmatched "KUBECONFIG" · package/config/sources.yaml

Scanned versions

VersionVerdictScoreScanned (UTC)
3.7.0Low risk02026-06-12
3.6.1Low risk02026-06-12
3.6.0Low risk02026-06-11
3.5.0Low risk02026-06-11
3.4.0Low risk02026-06-11
3.3.2Low risk02026-06-11
3.3.1Low risk02026-06-10
3.3.0Low risk02026-06-10
3.2.1Low risk02026-06-09
3.2.0Low risk02026-06-09
3.1.1Low risk02026-06-09
3.1.0Low risk02026-06-08
3.0.1Low risk02026-06-08
3.0.0Low risk02026-06-06
1.8.1Low risk02026-06-01
1.7.1Review602026-05-25
1.7.0Review602026-05-24
1.6.0Low risk02026-05-24

Related campaigns

Block this in CI

PkgRadar gates @thotischner/observability-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @thotischner/[email protected]